A flaw was found in Keycloak's OIDC... CVE-2024-1249

- AV AC AU C I A
发布: 2024-04-17
修订: 2024-04-17

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息